|
|
Subscribe / Log in / New account

sssd: access restriction bypass

Package(s):sssd CVE #(s):CVE-2011-1758
Created:May 5, 2011 Updated:May 11, 2011
Description:

From the Red Hat Bugzilla entry:

A flaw was introduced in SSSD 1.5.0 that, under certain conditions, would have sssd overwrite a cached password with the filename of the kerberos credential store (defined by krb5_ccache_template in sssd.conf). This could allow an attacker to gain access to an account without knowing the password if they knew the cached-credential string.

Alerts:
Fedora FEDORA-2011-5815 sssd 2011-04-22

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds